Professional Documents
Culture Documents
Bellingcat's Online Investigation Toolkit
Bellingcat's Online Investigation Toolkit
Welcome to Bellingcat’s freely available online open source investigation toolkit. You can follow our work on our
website, Twitter and Facebook. Feel free to suggest tools not yet listed here! This is version 3.8 (September 15,
2018).
A condensed version of the digital toolkit accessible for anyone with an internet connection, made by H I Sutton,
Aliaume Leroy, and Tony Roper. Download h erein higher resolution.
The list includes satellite and mapping services, tools for verifying photos and videos, websites to archive web pages,
and much more. The list is long, and may seem daunting. There are guides at the end of the document, highlighting
the methods and use of these tools in further detail. We also provide tailored digital forensics workshops.
Currently, I’m trying to find a better way to thematically structure this list and I’m working on a more extensive guide
with simple case-studies to the tools we use most. This will be an openly available and digital guide in English and
hopefully Arabic too. I will share a link here once it is published. Feel free to contact me with questions or suggestions
via email (christiaantriebert@bellingcat.com) or Twitter (@trbrtc).
To view an outline of the document, click “View” and then “Show document outline”.
1
Bing Maps Microsoft satellite and More recent and Difficult to check the bing.com/maps
mapping service. higher resolution date of the imagery
imagery than Google, (this tooldoesn’t work
e.g. in Afghanistan and anymore)
Iraq.
2
discount. Contact:
Artem Seredyuk
artem.seredyuk@eosd
a.com. EOS is in the
process of developing
a service provisionally
called EOS Media that
will be providing free
images and analysis of
major natural
disasters.
Google Earth Engine Open-access satellite Virtually any satellite Moderate and coarse https://earthengine.goo
imagery and analytical imagery collected from resolution imagery gle.com/
framework NASA, NOAA, USGS, rather than
etc. is available high-resolution
commercial imagery;
Learning curve with
Javascript
3
Google Photos
(formerly Panoramio)
Old Maps Online Find old maps through Easy-to-use, similar oldmapsonline.org
numerous databases browsing as the
all around the world. DigitalGlobe
catalogue.
OpenStreetCam openstreetcam.org
OpenStreetMap openstreetmap.org
4
of the planet’s
resources and citizens.
It is sponsored by the
World Resources
Institute and other
organizations.
Sentinel Hub A user-friendly place Updated every 5-10 Generally low apps.sentinel-hub.com
Playground for Sentinel 2/Landsat days with new resolution of 10m/px. /sentinel-playground
images. imagery, dependent on
cloud cover.
Ability to explore a
variety of GIS
variables eg NDVI or
NDWO. The EO
Browserfacilitates
time-lapse reviews.
Animaps Created custom Useful for timeline Not secure, and not http://www.animaps.co
animated maps. recording for well developed. m
investigations
5
Esri powerful mapping and Robust and full Requires a level of esri.com
analytics software featured account setup and
configurations that
may make some to
forget it.
Follow Your World track your points of Simple, easy to use, followyourworld.appsp
interest and manage dashboard for tracking. ot.com/
your email subscription
settings here.
6
Exiftool Read and Floss, Yet to encounter https://www.sno.p See forum and
manipulate Cross-platform any (Have only hy.queensu.ca/~p FAQ on linked
metadata for a and very easy to used on hil/exiftool/ page
vast number of file integrate into GNU/Linux).
types. Note: no scripts.
GUI
GooFile Extract metadata. Simple to use. Doesn't work well tools.kali.org/infor Ascii cinema
outside Kali mation-gathering/g
oofile
Image Forensics Web-based image Can easily identify Public access, 29a.ch/photo-foren
forensics tool. fake or doctored information not sics/#level-sweep
images private.
7
Splunk Extract metadata. Report grade Not simple to set blog.sweepatic.co Sweepatic.com
analysis and up and deploy. m/metadata-hacke
presentation. rs-best-friend
Social Media
Facebook
8
particular location.
Snapchat
Tumblr
9
YouTube
Transport
Air
Name Description Pros Cons Link Guides
10
ar/desktop.html
FlightAware flightaware.com
PlaneFinder planefinder.net
Marine
MarineTraffic marinetraffic.com
VesselFinder vesselfinder.com
Railway
Trains Full interactive Denmark, France
,
maps of various Germany,
railway networks Netherlands,
in European Poland
countries.
Misc
WikiRoutes Public transport wikiroutes.info
database.
11
DNS History Collection of Free, simple and Sometimes limited DNS History
historical DNS easy to use. in availability.
information.
Shodan Internet of things Can find heaps of Lives in the gray shodan.io
search engine. misconfigured zone...
network-connecte
d devices.
● Network-Tools
● Open Site Explorer
● People search
○ Peekyou, peekyou.com
○ Pipl, the world largest people search engine, find persons behind an e-mail
address, social media username, or phone number, pipl.com
○ Yasni, yasni.com
○ Zaba Search, only US, zabasearch.com
○ publicrecords.searchsystems.net
○ cemetery.canadagenweb.org/search.html
○ opencorporates.com
○ www.numberway.com/- a list of URLs to local White Pages and Yellow Pages,
with the description in English. Useful in finding people and companies.
● Robtex
12
● Search IRC
● Shodan Computer Search
● Utrace
● ViewDNS
● DN
SHistoricalData, research.dnstrails.com
● SpyOnWeb, to retrieve websites by their Tracking codes,spyonweb.com
● Whois, for domain search and information, whois.netor whois.icann.org
Dumpster Diver Tool to search for Easy, free and Nil cons. github.com/securin
secrets in various opensource g/DumpsterDiver
file types.
13
Miscellaneous
Name Description Pros Cons Link Guides
14
TimelineJS by Make an
Knight Lab interactive timeline timeline.knightlab.
of events. com
Visual vis.occrp.org
Investigative
Scenarios (VIS)
15
○ Includes multiple guides (website data scraping, Google Dorking etc.), resource
links, and examples of successful investigations in various fields
● First Draft News’resources, some of which have been written by Bellingcat members,
firstdraftnews.com/resources, for example:
○ How to Get Started in Online Investigations
● Flash Environmental Assessment Tool, for identifying harmful substances and their
effect on the environment after industry has been destroyed:
https://docs.unocha.org/sites/dms/Documents/FEAT_Version_1.1.pdf
● Poynter, fact-checking how-to guides, factcheckingday.com/#how-to
● Poynter, fact-checkers code of principles, poynter.org/fact-checkers-code-of-principles
● Verification Handbook(PDF) is a great place to go to find tools to verify digital
information, verificationhandbook.com
● Washington Post, guide, washingtonpost.com/news/fact-checker
● Washington Post, fact-checker tool, washingtonpost.com/news/fact-checker
● WITNESS
○ Activists' Guide to Archiving Video
○ Video As Evidence: Verifying Eyewitness Video
WEAPONS
Data Visualisation
Name Description Pros Cons Link Guides
Maptia maptia.com
Visual vis.occrp.org
investigative
scenarios
16
● Check for every digital service you use whether you have enabled two-factor
authentication (2FA), twofactorauth.org
● Security in a box guide: https://securityinabox.org/en/
● Tech Solidarity, techsolidarity.org
○ Basic Security Guide, do and don’ts for basic security when using a laptop and/or
mobile device, techsolidarity.org/resources/basic_security.htm
Syria
Maps lib.utexas.edu/maps/sy
ria.html
17
Company Registries
https://challenge.burnerapp.com/
Expert/Source Tools
Name Description Pros Cons Link Guides
18
- https://www.numberway.com/- a list of URLs to local White Pages and Yellow Pages, with the description in
English. Useful in finding people and companies (I've already placed it in the google doc)
Paint.net
Namechk.com
Very good for identifying online accounts with a username. Simply plug the username in and this tool will
identify where there are users using that name.
19